CVE-2026-33825
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
CVSS
7.8
High
EPSS
6.7%
p93
KEV
YES
Apr 22, 2026
Exploit Today
78
0-100
Published: Apr 14, 2026 · Last modified: Jul 24, 2026 · CWE-1220
Product
Microsoft / Defender
Vulnerability
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Added to KEV
Apr 22, 2026
Remediate by
May 6, 2026
Known ransomware use
Yes
Summary description
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825 ; https://nvd.nist.gov/vuln/detail/CVE-2026-33825
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.